By Kevin Nikkhoo  Just as business critical as perimeter security, having strong internal controls to manage users is important. Using cloud-managed security tools can help reduce incidents.
So much is written about the events outside your perimeter; those nefarious and shadowy individuals and offshore... May. 15, 2012 10:00 AM EDT Reads: 417 |
By Steve Hanna  A recent article in Government Computer News raised the topic of FISMA reporting, specifically describing the “pessimism” of many USG agencies over meeting the September 2012 deadline for “using continuous monitoring to meet Federal Information Security Management Act reporting require... May. 4, 2012 10:00 AM EDT Reads: 805 |
By Jared Day  When we aren’t fighting crime, taking over the world, or enjoying a good book by the fire, we here on the eEye Research team like to participate in the Any Means Possible (AMP) Penetration Testing engagements with our clients. For us, it’s a great way to interact one-on-one with IT fol... Apr. 5, 2012 10:00 AM EDT Reads: 1,472 |
By David Gibson  In most organizations today, there is sensitive data that is overexposed and vulnerable to misuse or theft, leaving IT in an ongoing race to prevent data loss. Packet sniffers, firewalls, virus scanners, and spam filters are doing a good job securing the borders, but what about insider... Mar. 5, 2012 06:00 AM EST Reads: 983 |
By Tad Anderson  The CERT Guide to Insider Threats: How to Prevent, Detect, and Respond to Information Technology Crimes (Theft, Sabotage, Fraud) (SEI Series in Software Engineering) .
Working as a Software Architect one of the main concerns we always have is Security. At an application level that can... Feb. 24, 2012 09:15 AM EST Reads: 880 |
By Tomer Teller  Quick Response (QR) codes are intended to help direct users quickly and easily to information about products and services, but they are also starting to be used for social engineering exploits. This article looks at the emergence of QR scan scams and the rising concern for users today.... Feb. 23, 2012 06:45 AM EST Reads: 1,223 |
By Shaul Efraim  Managing access to confidential information and application resources via firewalls is the foundation of network security, and firewall audits are central to any mature network security process. However, relying on security and network experts to review rules across multiple firewall z... Jan. 30, 2012 07:30 AM EST Reads: 1,508 |
By Vincent M. Schiavo  Companies across all industries are fighting to secure their proprietary and confidential data behind firewalls and complex passwords; unfortunately, the reality is that this data is most likely still slipping through the cracks. The introduction of employee-owned devices and the consu... Jan. 14, 2012 02:00 PM EST Reads: 1,391 |
By David Dodd  The purpose of this article is to describe some tools and techniques in performing the planning, scoping, and recon portion of a penetration test. In covering these tools and techniques the reader will learn how to use them to find vulnerabilities in their organization and help improve... Jan. 9, 2012 04:00 AM EST Reads: 2,129 |
By Dana Gardner  Joe Menn explores the current cyber-crime landscape, the underground cyber-gang movement, and the motive behind governments collaborating with organized crime in cyber space.
Maybe you can make your enterprise a little trickier to get into than the other guy’s enterprise, but crime pa... Jan. 6, 2012 08:00 AM EST Reads: 2,138 |
By Tim Matthews  There are some technological concepts that simply go better together. Consider the cloud and information explosion; the cloud offers the potential for unlimited storage for a torrent of ever-increasing data. Another example is virtualization and IT agility; strategic virtualization imp... Jan. 4, 2012 05:15 AM EST Reads: 2,716 |
By Gorka Sadowski  We saw what typically happens when trying to use static rule-based log correlation to perform real-time incident management... combinatory explosion and lack of scalability. How do you automate non-deterministic attacks in a few discrete steps???
Today, we'll look at more scenarios fo... Dec. 20, 2011 09:00 AM EST Reads: 2,207 |
By Dana Gardner  In just the past year, the number of attacks are up, the costs associated with them are higher and more visible, and the risks of not securing systems and processes are therefore much greater. Some people have even called the rate of attacks a pandemic.
The path to reducing these risk... Dec. 2, 2011 06:45 AM EST Reads: 2,152 |
By Michael Podszywalow  You’ve spent months fixing the red items on an internal audit report and just passed a regulatory exam. You’ve performed a network vulnerability assessment and network pen test within the last year and have fixes in place. You’ve tightened up your information security policy and recent... Nov. 24, 2011 03:00 PM EST Reads: 1,949 |
By Georgiana Comsa  In a recent blog post, Gary Sevounts, VP of marketing at Zetta, looks at the most popular offsite backup solutions for organizations with smaller budgets that can't afford a data center, but need their mission-critical data to be protected. Sevounts lists four options: tape, USB, mirro... Oct. 28, 2011 11:51 AM EDT Reads: 1,307 |
By David Dodd  The goal of the scanning phase is to learn more information about the target environment and discover openings by interacting with that target environment. This article will look at some of the most useful scanning tools freely available today and how to best use them. During this proc... Oct. 12, 2011 01:00 PM EDT Reads: 1,837 |
By Jim Kaskade  The security community has a growing number of influential and important people, especially as the industry rises to meet the need to address more advanced security threats, such as targeted attacks. But how does a company in the security industry truly identify the influential people?... Sep. 8, 2011 02:50 PM EDT Reads: 19,098 Replies: 4 |
By Marc Chanliau  The recent spike in insider threats, coupled with a rise in compliance considerations, has forced organizations to ensure only authorized users access sensitive application functionality and data. Historically, user entitlements or authorization logic has been embedded inside an applic... Aug. 25, 2011 10:15 AM EDT Reads: 7,105 |
By Dana Gardner  How can all the players in a technology ecosystem gain assurances that the other participants are adhering to best practices and taking the proper precautions? Jul. 29, 2011 10:00 AM EDT Reads: 9,098 |
By David Dodd  We are using the local port forwarding bound on a victim host so when we execute the route command and exploit internal hosts we can map them back to our initial victim, through the meterpreter connection and back to us.
The Metasploit Framework is a penetration testing toolkit, explo... Jun. 29, 2011 10:00 AM EDT Reads: 3,997 |
By Gorka Sadowski  Last week we saw that a proper Log Management tool is a powerful tool to catch the bad guys.
Advertise your use of such a tool and you will send a clear signal to would-be attackers that they will be caught, which will act as a powerful deterrent, and curb bad behaviors.
A 2004 study... Jun. 16, 2011 02:15 PM EDT Reads: 1,991 |
By Dana Gardner  The OTTF’s purpose is to shape global procurement strategies and best practices to help reduce threats and vulnerabilities in the global supply chain.
The framework outlines industry best practices that contribute to the secure and trusted development, manufacture, delivery and ong... Feb. 23, 2011 11:20 AM EST Reads: 2,383 |
By Dana Gardner  This is really not about adding some security band-aid onto a technology or a product. It's really about the fundamental attributes or assurance of the product or technology that’s being produced.
The OTTF is a group that came together under the umbrella of The Open Group to identify ... Feb. 22, 2011 02:54 PM EST Reads: 3,145 |
By Bill Roth  The major theme of this year’s RSA Conference is, guess what, security. This is the largest security show of the year, and its clearly a big deal, since it covers both sides of the Moscone Center in San Francisco. As of 10 a.m. on Monday, preparations are still being made. The show off... Feb. 14, 2011 03:24 PM EST Reads: 2,749 |
By Christos K. Dimitriadis  As enterprises struggle to remain profitable in an ever-changing risk environment, the current economic crisis has elevated the need for effective business risk management. Information security is a key parameter that affects business risk. The academic definition of information securi... Feb. 9, 2011 06:00 AM EST Reads: 3,889 |
By Peter Weger  The WikiLeaks security fiasco has shed a lot of light on document security and its inherent irony: namely that the more confidential a document is, the more it’s likely to be shared.
Web Security Journal reached out to the CEO of Brainloop, Peter Weger, to discuss the notion of so-... Feb. 5, 2011 05:15 AM EST Reads: 2,796 |
By Gorka Sadowski  Over the next few weeks, we'll investigate how the expression "An ounce of prevention is worth a pound of cure" could also be applied to the IT world, and what are the tools to foster preventive security through behavior modification.
When looking at IT security, it seems that most of... Feb. 1, 2011 07:00 PM EST Reads: 2,850 |
By David Rowe  Users are the weakest link when it comes to information security. Without intending to, they cost more money in security breaches than outside hackers. This is why all regulations require the demonstration of strong access security. But focusing purely on regulatory compliance proofs a... Jan. 12, 2011 12:15 PM EST Reads: 3,237 |
By Security News Desk  There's been a flurry of discussion this week among Internet and Web standards heavy-hitters around WebSocket, the new communications protocol supported in Chrome 4 and Safari 5. What was the main issue? Is there some kind of fundamental security vulnerability with the WS protocol? Web... Dec. 12, 2010 02:30 AM EST Reads: 14,006 |
By Maureen O'Gara  Right before Christmas, the White House tapped Microsoft’s long-ago chief security officer, the CEO of the non-profit Information Security Forum Howard Schmidt as head of US cyber security.
Despite the national priority, between pressure from US companies and reported infighting am... Dec. 28, 2009 11:30 AM EST Reads: 4,648 |
By Peter Silva  I had a different name for this blog entry but just ‘Jump Drive’ is an awful blog title. They go by many names; jump drive, USB drive, flash drive, memory stick and a few others, but removable media is a serious threat to IT organizations. Graduating from floppy disks, as early as 20... Sep. 12, 2009 06:30 PM EDT Reads: 6,250 |
By Mark O'Neill  Joe McKendrick kicks off a thread on the current state of SOA Security. As usual, most discussion of SOA Security applies to "how SOA can be made secure". This is understandable. And, as some commentators have pointed out, there is a body of Best Practice out there on how to secure ser... Sep. 8, 2009 01:00 PM EDT Reads: 5,418 |
By Devi Gupta  You don't have to be a chief information officer to realize that security is becoming a corporate concern as more business is transacted on the Web. The mounting fears are well founded. Web attacks are growing in sophistication. Data is flowing faster and to more applications and more ... Mar. 9, 2009 10:15 AM EDT Reads: 6,811 |
By Prat Moghe  There are many reasons why a data security strategy could self-destruct, not the least of which is a new breed of highly motivated data thieves who stand to make a considerable profit on customer and other sensitive information in data centers. We're often so mired with putting out dat... Nov. 10, 2008 01:08 PM EST Reads: 4,141 |
By SOA News Desk Layer 7 Technologies announced its go-to-market partnership with Steria Benelux. Steria will act as a channel partner for Layer 7's SOA gateway products in Belgium to offer leading SOA security, governance solutions and support to its current and prospective customers. May. 28, 2008 03:30 PM EDT Reads: 7,046 |
By Erika Delgado  Spending time with my parents over the holidays got me thinking about the differences between this generation and the previous one. My parents expect to spend a certain amount of time and effort managing certain aspects of their lives. For example, when they drive to an unfamiliar vaca... May. 22, 2008 08:00 AM EDT Reads: 7,705 |
By Mike Pellegrini  Composite applications are made up of discreet services that have been tried and proven reliable, but building an orchestration that incorporates services that come from several sources, some of them outside of the company, could introduce testing hazards beyond just bad output. For ex... May. 5, 2008 06:00 PM EDT Reads: 5,290 |
By Scott Morrison  Is SOA ready to move from the whiteboards and into production IT? As you might have guessed, the answer remains a disappointing sort of. The issue comes down to tools and infrastructure, and the fact that only some SOA components are mature and easy to source. Aug. 20, 2007 08:45 AM EDT Reads: 14,894 Replies: 1 |
By Rajiv Gupta  As the name suggests, a Service Oriented Architecture is one where application functionality is packaged as autonomous services that adhere to industry standard interfaces (WSDL, SOAP), and the services are then deployed in an IT architecture that makes for their most effective use. T... Apr. 14, 2007 04:15 PM EDT Reads: 20,893 |
By Kevin Smith  When SOAP-based Web Services solutions began appearing five years ago, one of the major challenges was securely propagating end-user identity in Web Service chaining scenarios. Certainly a user could authenticate to a portal, and that portal could talk to a Web Service that talks to an... Oct. 19, 2006 01:15 PM EDT Reads: 12,287 Replies: 1 |